APSB26-138: September's Magento Patch Doesn't Contain the Zero-Day Fix
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Emyrix Blog
Every post tagged patches, newest first.
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Adobe's August 2026 patch fixes seven Adobe Commerce and Magento vulnerabilities. The worst lets someone take over a customer account without logging in, and attacks started within a day.
Adobe's July 2026 bulletin listed Magento 2.4.9 among the affected versions. Why the newest release line needs the most patch discipline, not the least.
Magento 2.4.8 is supported to 2028, which makes it easy to defer patching. Adobe's cadence changed in 2026 — here's the patch process that keeps up with it.
Magento 2.4.7 is still supported until 2027 — but Adobe's July 2026 bulletin lists 2.4.7-p10 and earlier as vulnerable. Why patch level matters more than version number.
Working through one of these?
Upgrades, performance work, and emergency support for Magento, Adobe Commerce, Shopware, and custom Laravel builds.